Bug 1771301 (CVE-2019-15132)

Summary: CVE-2019-15132 zabbix: information disclosure in api_jsonrpc.php and index.php
Product: [Other] Security Response Reporter: Dhananjay Arunesh <darunesh>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED UPSTREAM QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: bennie.joubert, dan, ms, orion, volker27
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Zabbix 4.2 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2019-11-12 12:51:11 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1771302, 1771303, 1771304, 1771305, 1771306, 1771307    
Bug Blocks:    

Description Dhananjay Arunesh 2019-11-12 07:07:49 UTC
A vulnerability was found in Zabbix through 4.4.0alpha1 allows User Enumeration. With login requests, it is possible to enumerate application usernames based on the variability of server responses (e.g., the "Login name or password is incorrect" and "No permissions for system access" messages, or just blocking for a number of seconds). This affects both api_jsonrpc.php and index.php.

Reference:
https://support.zabbix.com/browse/ZBX-16532

Comment 1 Dhananjay Arunesh 2019-11-12 07:08:32 UTC
Created zabbix tracking bugs for this issue:

Affects: fedora-all [bug 1771302]


Created zabbix22 tracking bugs for this issue:

Affects: epel-6 [bug 1771303]
Affects: epel-7 [bug 1771304]


Created zabbix30 tracking bugs for this issue:

Affects: epel-7 [bug 1771305]


Created zabbix40 tracking bugs for this issue:

Affects: epel-7 [bug 1771306]
Affects: epel-8 [bug 1771307]

Comment 2 Product Security DevOps Team 2019-11-12 12:51:11 UTC
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.